Digital Privacy, Trust & Safety Consultant
Job description
About the role
You will own the end to end execution of digital privacy, trust and safety audit programs from scoping and methodology design through to executive facing reporting. You own the independent assessment of digital platforms, services, and systems against global privacy and trust and safety regulations using a combination of technical testing and compliance review. You own the identification of gaps, risks, and control failures that could impact user safety, data protection, and regulatory adherence. You own the delivery of clear, actionable, and remediation focused audit findings to both technical teams and organizational stakeholders. You own the role of trusted advisor, translating complex regulatory requirements into practical controls and testable outcomes for clients. You own the continuous learning required to keep pace with evolving privacy laws, platform features, and emerging trust and safety threats. You own the collaboration with internal specialists to integrate privacy by design principles and user safety considerations into audit planning. You own the successful execution of engagements that help clients navigate the ever changing cybersecurity and regulatory landscape while building real trust with their users.
Key facts
What you'll do
Conduct independent audits and technical testing of digital platforms, services, and systems against global privacy and trust and safety regulations.
Design and implement audit methodologies, testing protocols, and scoping approaches tailored to specific platform business models, risk profiles, and regulatory environments.
Execute compliance testing protocols covering user protections, data handling practices, content moderation systems, and data subject rights fulfillment mechanisms.
Identify gaps, weaknesses, and control failures in trust and safety controls, privacy by design implementation, and regulatory compliance processes.
Perform hands on testing of user reporting flows, account controls, data access, data deletion, and consent management interfaces to validate real world behavior.
Evaluate content moderation effectiveness, policy enforcement consistency, and transparency of decision mechanisms affecting user safety and trust.
Deliver detailed audit findings, risk ratings, and prioritized remediation guidance to technical teams, leadership, and regulatory stakeholders.
Collaborate with security, privacy, and product teams to integrate audit insights into secure development lifecycle and operational improvement initiatives.
Support the development and maintenance of reusable audit playbooks, checklists, and evidence collection templates for current and future engagements.
Maintain current awareness of global privacy regulations, emerging trust and safety standards, and platform policy updates that impact audit scope and testing approaches.
Requirements
Must be a United States citizen or national or possess authorization to work in the United States that does not expire in the near future.
Must be legally eligible to work in the United States without requiring sponsorship now or in the near future for this position.
Must be able to pass a criminal background check as a condition of employment for this role.
Must be able to pass a credit check as a condition of employment for this role.
Must be able to pass a drug screen as a condition of employment for this role.
Must be able to provide proof of identity and employment eligibility using documents that comply with Form I 9 requirements.
Must provide proof of COVID 19 vaccination or a valid medical or religious exemption to be considered for employment.
Must be willing to sign an NDA and abide by Coalfire policies regarding confidential information, acceptable use, and code of conduct.
Nice to have
Experience conducting digital privacy, trust and safety audits against global regulations and platform policies.
Hands on experience testing user protections, data handling practices, content moderation systems, and consent mechanisms.
Familiarity with privacy frameworks, data subject rights processes, and regulatory compliance reporting.
Understanding of risk rating methodologies, remediation guidance, and stakeholder communication in audit contexts.
Practical notes
Hours: Full time positions are typically 40 hours per week.
Travel: This role may require travel to client sites, audit locations, or training events, with advance scheduling typically required.
Visa: Sponsorship is not available for this role at this time.
Deadline: Please apply through the official portal with updated resume and required documentation by the specified posting deadline.